Unrated severityNVD Advisory· Published Jun 8, 2015· Updated May 6, 2026
CVE-2015-3905
CVE-2015-3905
Description
Buffer overflow in the set_cs_start function in t1disasm.c in t1utils before 1.39 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.
Affected products
3- cpe:2.3:a:t1utils_project:t1utils:1.38:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*+ 1 more
- cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:14.10:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- bugs.debian.org/cgi-bin/bugreport.cginvdExploit
- github.com/kohler/t1utils/issues/4nvdExploit
- ubuntu.com/usn/usn-2627-1nvd
- www.openwall.com/lists/oss-security/2015/05/13/9nvd
- www.openwall.com/lists/oss-security/2015/05/22/10nvd
- www.securityfocus.com/bid/74674nvd
- bugzilla.redhat.com/show_bug.cginvd
- github.com/kohler/t1utils/blob/master/NEWSnvd
- github.com/kohler/t1utils/commit/6b9d1aafcb61a3663c883663eb19ccdbfcde8d33nvd
- security.gentoo.org/glsa/201507-10nvd
News mentions
0No linked articles in our index yet.